Skip to main content

Set up a Kubernetes cluster

KubeNDT runs on top of your own Kubernetes cluster: the backend reads the kubeconfig mounted from the host, so the active kubectl context is the cluster KubeNDT will manage. This page summarizes how to prepare a suitable cluster. For the full step-by-step procedure see the Cluster Bootstrap Guide in the KubeNDT repository.

Requirements

  • Linux host (or Linux VMs for kubeadm).
  • Kubernetes 1.20+ with kubectl configured and working.
  • Docker and Docker Compose (to run the KubeNDT services).
  • Git (to clone the Meshnet CNI).
  • Recommended lab resources: 4 vCPU, 8 GB RAM.

Choose a scenario

The guide covers three setups; pick the one that matches your needs:

ScenarioToolBest for
Single-node labMinikubeQuick functional validation
Two-node local clusterkindReproducible multi-node testing
Two-node production-stylekubeadmCloser-to-production deployments

Example: single-node with Minikube

minikube start --driver=docker --cpus=4 --memory=8192 --disk-size=30g \
--extra-config=kubelet.allowed-unsafe-sysctls="net.ipv4.ip_forward,net.ipv6.conf.all.forwarding"
kubectl config current-context
kubectl get nodes -o wide
Why the allowed-unsafe-sysctls flag?

Some KubeNDT node types (Linux switches, OVS nodes) set net.ipv4.ip_forward and net.ipv6.conf.all.forwarding via pod sysctls. Without this flag the kubelet rejects those pods with SysctlForbidden.

Install the Meshnet CNI (required)

KubeNDT uses the Meshnet CNI for the L2/L3 overlays between nodes. The same installation works for every scenario:

git clone https://github.com/networkop/meshnet-cni.git
cd meshnet-cni/
kubectl apply -k manifests/base

Validate the cluster

Run these checks after creating the cluster and installing Meshnet:

kubectl get nodes -o wide
kubectl get pods -A
kubectl get ds -A | grep -i meshnet
kubectl get crd | grep -E 'topologies.networkop.co.uk|network-attachment-definitions.k8s.cni.cncf.io'
kubectl api-resources | grep -i topology

You are ready when:

  • All nodes are Ready.
  • The Meshnet workloads are running.
  • The topology CRD is registered and discoverable.

Once the cluster is ready, continue with Getting started to run KubeNDT and deploy your first topology.